CVE-2019-16894 | inoERP up to 4.15 Deserialization download.php sql injection (EDB-47426)
A vulnerability classified as critical has been found in inoERP up to 4.15. This affects an unknown function of the file download.php of the component Deserialization. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2019-16894. The attack is possible to be carried out remotely. Moreover, an exploit is present.